{
  "id": 10687249,
  "title": "ShinyHunters hackers are going after Oracle systems once again - here's what we know",
  "url": "https://urgent.news/2026/09/29/shinyhunters-hackers-are-going-after-oracle-systems-once-again-heres",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-29T12:05:00.000Z",
  "source": {
    "name": "TechRadar",
    "slug": "techradar",
    "url": "https://www.techradar.com/pro/security/shinyhunters-hackers-are-going-after-oracle-systems-once-again-heres-what-we-know"
  },
  "original_language": "en",
  "account": "ShinyHunters, notorious data extortionists, are once again targeting Oracle's PeopleSoft systems. In June 2026, they exploited a critical zero-day vulnerability in the PeopleSoft Environment Management Hub (PSEMHUB) servlet, allowing them to execute arbitrary code and deploy web shells. Oracle released a patch for CVE-2026-35273 on June 10, 2026, and added the vulnerability to the Known Exploited Vulnerabilities (KEV) catalog on June 12.\n\nShinyHunters have now discovered a way to bypass mitigation measures implemented in response to the initial exploit. By URL-encoding a single character in the request path, they can bypass web application firewall (WAF) rules that previously blocked the vulnerable PSEMHUB endpoint. This new attack vector is now being used against organizations globally, not just higher education institutions, targeting a wide range of sectors, including technology, healthcare, government, and agriculture.\n\nMandiant and Google's Threat Intelligence Group (GTIG) recommend several steps for organizations affected by this threat. First and foremost, they should apply Oracle's patch for CVE-2026-35273, which addresses the underlying vulnerability. Additionally, organizations should disable the Environment Management Hub (EMHub) service in multi-server configurations or remove the PSEMHUB application entirely in single-server configurations. They should also search their PeopleSoft access logs for requests to /PSEMHUB) and its percent-encoded variants, as well as inspect the /webserv/ /applications/peoplesoft/PSEMHUB.war/ directory for any stray or unauthorized files. Finally, credentials associated with the PeopleSoft application service account should be rotated, and outbound traffic from PeopleSoft hosts should be monitored for any suspicious activity.",
  "summary": "Mitigations are no longer mitigating, and patching is now the only method of defense.",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}